Invite a user
Send the invite from the Invites section: the user receives the email and sets their password themselves.
Users, invites, roles, MFA reset, branding, email, SSO, devices, sessions and API keys: the LoginMaster Tenant console is the panel from which you govern your users' identity every day. Here is what you actually do, item by item.
Credentials with Argon2id + split-salt · dual-signature RS256 tokens (Tenant + Cloud).

Each console area maps to a real operation the IT team performs on users and projects.
Invite who you need, set enablement or deletion and assign one of the available roles: admin, admin_tenant, manager, user, technician, api_user.

The user opens a request, the admin approves it from the console. TOTP is per project, with an enrolment grace period, deactivation for non-compliance and recovery codes.

Set logo, colors and name — inherited by projects — and customize email templates (LiquidJS + MJML) with it/en i18n and RTL support, per tenant or per project.

Configure single sign-on in OAuth 2.0/OpenID Connect to Google Workspace and Microsoft Entra ID (brokering), also per project.

Manage machine identities: user/device pairs, M2M API keys and AWS IoT Core integration via X.509 certificates and the Thing lifecycle.

Revoke sessions with server-side logout and manage API keys: creation, rotation, enablement and disablement for programmatic access.

What is available in the console today and what is on the roadmap. No overselling: anything not present is clearly stated as such.
In the meantime, provisioning happens via REST API and TypeScript/.NET SDKs; SSO is OAuth 2.0/OIDC to Google and Entra ID.
The recurring tasks an administrator performs from the console once everything is in production.
Send the invite from the Invites section: the user receives the email and sets their password themselves.
Choose among admin, admin_tenant, manager, user, technician and api_user to define what each person can do.
The user opens an MFA reset request, you approve it from the console: no codes shared over chat.
Edit the templates (LiquidJS + MJML) with it/en i18n and RTL support, per tenant or per project.
Perform server-side logout and revoke a user's active sessions in case of a lost device.
Create, rotate or disable API keys for programmatic access and M2M integrations.
Disable or delete the account with Full or Local deletion, for granular GDPR right-to-be-forgotten.
We'll show you the Tenant console with real data: users, roles, MFA reset, branding, SSO and API keys. Book a demo with our team.